IoT Will Change (Almost) Everything In Cybersecurity

The Internet of Things is growing fast, with an estimated 8.4 billion devices expected to be connected this year. 

As a result of that rapid expansion, the IoT is reshaping the way in which we think about corporate cyber-security by increasing the attack surface, potentially adding billions of network points of entry for cyber-criminals, each one an additional target to be compromised. 

Gartner put security at the top of its list of the top 10 IoT technologies for 2017 and 2018, and recent research validates the high priority of cybersecurity and connected things among businesses. One recent survey at Black Hat USA 2016 revealed 70 percent of IT experts who responded indicated that their organisation wasn't prepared for IoT-related threats.

While these statistics are real, there also exists a great deal of hype in the market, painting a grave portrait of the IoT and its unique requirements as the grim reaper for businesses. IoT security is a real concern, with open-source cyber-threats like Mirai already showing its potential, but businesses shouldn't believe every scary tale they hear. An attack on any one endpoint doesn't necessarily have to mean all systems are compromised or crippled.

Organisations looking to build or adopt connected devices should educate themselves on how additional endpoints change their threat-scape, and should seek to address a few key questions:

What New Vulnerabilities Is the IoT Creating for the Network? 

New vulnerabilities are created not just by the expansion of entry points, but by the nature of those entry points. Some of the more common vulnerabilities and concerns that businesses need to prepare for include:

• Insecure Web interfaces: "Internet" is in the name, so step one of IoT security is to make certain the connections themselves are secure. 
• Insecure endpoints: Each endpoint is open to an attack, so any that aren't equipped with antivirus software could be infected with malware, opening up the gates to the rest of the network. Businesses will need to keep a watchful eye on how endpoints are behaving and interacting with the rest of the network. 
• Mobile interfaces: The IoT happens everywhere, so ensuring a secure mobile strategy is imperative, including monitoring credentials and any accidental exposure.
How can Business address IoT security/vulnerabilities? 
The changes to the attack surface aren't beyond our abilities to address. Business can do a few simple things to increase their IoT security from the start:
• Change all default passwords. Simple cybersecurity best practices, like always resetting default passwords, will continue to be a vital first step in the age of the IoT. 
• Like changing the password, using an encrypted connection whenever one is available is generally a good cybersecurity rule of thumb that helps to mitigate the risk of attack on the many endpoints within the IoT.
• Create guidelines to quickly call out anomalous behavior of sensors. Sensors perform a very specific task or set of tasks, so detecting any suspicious behavior should be relatively simple if the technology and personnel monitoring the network understand which behaviors are authorized upfront.

How Is the IoT Changing the Future of Securing Businesses? 

In many ways, securing an IoT-enabled business requires much of the same, but the game has changed in that the sheer volume of endpoints, and thus the area to secure, is quickly multiplying. Businesses will need to move beyond traditional network and endpoint security, and be diligent in monitoring all network connections. 
Detection and response strategies will need to become more closely integrated with cybersecurity practices, and IT departments will be most effective by combining the power of technology and human oversight to keep a watchful eye over expanded attack surfaces.

This is particularly true for new and emerging threats, and an overreliance on technology will result in undue complacency, which is exactly what the cybercriminals want in prospective targets.

IoT Journal:

You Might Also Read: 

Internet of Things Brings Threats To Security:

The Internet of Things Will Be Even More Vulnerable to Cyber Attacks:

Data Breaches & The Internet of Things:

Guide To The Internet of Things:

 

« Information Security Forum Launches - Threat Intelligence Report
Facebook Deploys AI To Block Terror Propaganda »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

authen2cate

authen2cate

Authen2cate offers a simple way to provide application access with our Identity and Access Management (IAM) solutions for enterprise, small business, and individual customers alike.

IoT Security Foundation (IoTSF)

IoT Security Foundation (IoTSF)

IoTSF is a collaborative, non-profit organisation with a mission to raise the quality and drive pervasive security in the Internet of Things.

Applause

Applause

Applause provides real-world software testing for functionality, usability, accessibility, load, localization and security.

Fortress Group

Fortress Group

Fortress is specialized in confidential and discrete recruitment solutions and temporary staffing in the field of security and risk management.

Maritime Cybersecurity Center (MCC)

Maritime Cybersecurity Center (MCC)

Maritime Cybersecurity Center is a not-for-profit organization focused on regional cybersecurity excellence and readiness, with a special emphasis on the maritime community.

vdiscovery

vdiscovery

vdiscovery is a provider of proprietary and best-in-breed solutions in computer forensics, document review, and electronic discovery.

ecsec

ecsec

ecsec is a specialized vendor of security solutions including information security management, smart card technology, identity management, cloud computing and electronic signature technology.

CYRail

CYRail

CYRail project will analyse threats targeting Railway infrastructures and develop innovative attack detection and alerting techniques.

C11 Cyber Security & Digital Innovation Centre

C11 Cyber Security & Digital Innovation Centre

C11 is working with local and national partners to develop talent and bring brilliant minds and brilliant businesses together.

SimSpace

SimSpace

SimSpace is the visionary yet practical platform for measuring how your security system responds under actual, sustained attack.

Vigilant Technology Solutions

Vigilant Technology Solutions

Vigilant is a global cyber security technology company offering solutions to manage entire IT & cyber security lifecycles.

D2 Network Associates (D2NA)

D2 Network Associates (D2NA)

D2NA help businesses deliver and achieve their goals, through innovative IT solutions, robust cyber security services and proactive IT managed services.

NetTech

NetTech

NetTech’s Managed CyberSecurity and Compliance/HIPAA services are designed to help your company prevent security breaches and quickly remediate events if they do happen to occur.

Pointsharp

Pointsharp

Pointsharp delivers software and services that help organizations secure data, identities, and access in a user-friendly way.

DynTek

DynTek

DynTek delivers exceptional, cost-effective professional IT consulting services, end-to-end IT solutions and managed IT services.

BreakPoint Labs

BreakPoint Labs

BreakPoint Labs is dedicated to providing the methods and means for sustainable, measurable, and effective cybersecurity operations.